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Foreword 



This Technical Specification has been produced by the 3rd Generation Partnership Project (3 GPP). 

The contents of the present document are subject to continuing work within the TSG and may change following formal 
TSG approval. Should the TSG modify the contents of the present document, it will be re-released by the TSG with an 
identifying change of release date and an increase in version number as follows: 

Version x.y.z 

where: 

X the first digit: 

1 presented to TSG for information; 

2 presented to TSG for approval; 

3 or greater indicates TSG approved document under change control. 

y the second digit is incremented for all changes of substance, i.e. technical enhancements, corrections, 
updates, etc. 

z the third digit is incremented when editorial only changes have been incorporated in the document. 
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Scope 



This document specifies the stage 2 system description for providing mobiHty between 3 GPP Wireless Local Area 
Network Interworking (I-WLAN) and 3 GPP Systems. It is to define a technical solution based on the working 
principles of DSMIPv6 [7] with necessary enhancement of the I-WLAN architecture for supporting mobility and 
roaming between 3 GPP- WL AN Interworking system and 3 GPP Systems so that ongoing 3 GPP PS based services can 
be maintained with minimal impact on the end-user's perceived quality on the services at a change of the access network 
(between I-WLAN and 3GPP Access Systems. 

The specification includes both non-roaming and roaming scenarios and covers all aspects, including mobility between 
3 GPP Systems and I-WLAN with access authentication and charging. 



References 



The following documents contain provisions which, through reference in this text, constitute provisions of the present 
document. 

• References are either specific (identified by date of publication, edition number, version number, etc.) or 
non-specific. 

• For a specific reference, subsequent revisions do not apply. 

• For a non-specific reference, the latest version applies. In the case of a reference to a 3GPP document (including 
a GSM document), a non-specific reference implicitly refers to the latest version of that document in the same 
Release as the present document. 

[I] 3GPP TR 2L905: "Vocabulary for 3GPP Specifications". 

[2] 3GPP TS 23.234: "3GPP Systems to Wireless Local Area Network (WLAN) Interworking; 

System Description" . 

[3] 3GPP TS 23.060: "General Packet Radio Service (GPRS); Service Description; Stage 2". 

[4] 3GPP TS 23.203: "Policy and Charging Control Architecture". 

[5] 3GPP TS 33.234: "3G security; Wireless Local Area Network (WLAN) interworking security". 

[6] 3 GPP TS23.402: "Architecture Enhancements for non-3 GPP accesses". 

[7] IETF Internet-Draft, draft-ietf-mip6-nemo-v4traversal-03.txt: "Mobile IPv6 support for dual stack 

Hosts and Routers (DSMIPv6)". 

[8] IETF RFC 3775: "Mobility Support in IPv6". 

[9] IETF RFC 4306, "Internet Key Exchange Protocol Version 2" . 

[10] IETF RFC 3748: "Extensible Authentication Protocol (LAP)". 

[II] IETF RFC 4877: "Mobile IPv6 Operation with IKEv2 and the Revised IPsec Architecture". 

[12] IETF RFC 4739: "Multiple Authentication Exchanges in the Internet Key Exchange (IKEv2) 

Protocol". 

[13] 3GPP TS 29.061 : "Interworking between the PubHc Land Mobile Network (PLMN) supporting 

Packet Based Services and Packet Data Networks (PDN)". 
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3 Definitions and Abbreviations 

3.1 Definitions 

For the purposes of the present document, the definition given in TR 21.905 [1] and the following apply. A definition 
given in the present document takes precedence over the same definition, if any, in TR 21.905 [1]. 

Home Agent Access Point Name (HA-APN): Is used to identify a specific PDN and a point of interconnection to that 
network (Home Agent). 

3.2 Abbreviations 

For the purposes of the present document, the abbreviations given in TR 21.905 [1] and the following apply. An 
abbreviation defined in the present document takes precedence over the definition of the same abbreviation, if any, in 
TR 21.905 [1]. 

APN Access Point Name 

CoA Care-of-address 

DHCP Dynamic Host Configuration Protocol 

DNS Domain Name System 

DSMIPv6 Dual-Stack MIPv6 

EPS Evolved Packet Systems 

GGSN Gateway GPRS Support Node 

GTP GPRS Tunnelling Protocol 

HA Home Agent 

I-WLAN Interworking WLAN 

MIP Mobile IP 

MIPv6 Mobile IP version 6 

MN Mobile Node 

PDP Packet Data Protocol, e.g. IP 

SGSN Serving GPRS Support Node 

UE User Equipment 



4 High-Level Requirements and Principles 

4.1 General Requirements 

- Access to 3 GPP and internet services shall be supported. 

- Smooth migration from legacy network with minimal impacts on dual mode UEs, I-WLAN and 3GPP systems 
shall be possible. 

Architecture, functions and procedures described in I-WLAN interworking TS 23.234 [2] and GPRS 
TS 23.060 [3] shall be re-used as basis. 

4.2 Architecture Requirements 

- Mobility for PDG based I-WLAN architecture shall be supported. 

- Both IPv4 and IPv6 addresses shall be supported 

- Quality of service shall be supported when the UE moves between I-WLAN and 3 GPP systems 

- I-WLAN and 3GPP QoS mechanisms defined in TS 23.234 [2] TS 23.060 [3] and TS 23.203 [4] shall be 
re-used. Additionally, the Home Agent shall be able to provide transport IP QoS e.g. DiffServ support similarly 
as defined for PDG in TS 23.234 [2]. 
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4.3 Mobility Requirements 



Service continuity between 3 GPP packet switched network and I-WLAN with IP address (es) preservation shall 
be supported. 

Multiple parallel sessions under the same APN shall be maintained when the UE moves between 3GPP PS 
network and I-WLAN. Also the mobility for the UE with multiple PDN connectivity should be supported. 

- Interruption time of the operators' services or applications being provided to the end user shall be minimized. 

- It shall be possible to notify to the user the change of the access networks, 3GPP PS system or I-WLAN. 

- It shall be possible to disable the mobility function where applicable to the operators' needs. 

4.4 Roaming Requirements 

- Mobility with re-use of roaming architecture interface(s) and protocol(s) in a visited PLMN shall be possible. 



4.5 Charging Requirements 



- It shall be possible to re-use existing policy control and charging (PCC) rules and mechanisms as defined in 
TS 23.203 [4]. 

- Charging differentiation capability based on radio access type shall be enabled. 

Use of common billing system for 3GPP PS system and the I-WLAN access shall be possible. 

4.6 Security Requirements 

- Existing security measures taken by the end users and the operators shall not be compromised. 

- It shall be possible for operators to apply common access control based on TS 33.234 [5] regardless of the 
change of the accesses by the UEs. 

- The operators shall be able to apply legal interception. 



Concepts and Architecture Model 



This specification is based on the architectural/functional/procedural definitions described in (WLAN Interworking) 
TS 23.234 [5] and (GPRS) TS 23.060 [3]. 

I-WLAN Mobility solution shall allow the operator to configure a type of access (e.g. 3GPP access) as the "home link" 
for DSMIPv6 purposes. 



5.1 General Concepts 



5.2 Architecture Reference Model 
5.2.1 Home Mobility Service Architecture 

The Home Mobility Service architecture refers to the case where the Home Agent function locates at HPLMN. Whether 
the user is roaming or not roaming in the underlying access system and/or whether the illustrated H3 reference point 
spans across different administrative domains is not relevant for this specification. 
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Figure 5.2.1-1 : Home Mobility Service Architecture for l-WLAN Mobility 

NOTE: The architecture is compatible with pre-Release 8 PDG and GGSN. 

5.2.2 Visited Mobility Service Architecture 

The Visited MobiHty service architecture refers to the case where the Home Agent function locates outside of the 
HPLMN. Whether the user is roaming or not roaming in the underlying access system and/or whether the illustrated H3 
reference point spans across different administrative domains is not relevant for this specification. 
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Figure 5.2.2-1 : Visited Mobility Service Architecture for l-WLAN Mobility 
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5.3 High Level Functions 

5.3.1 General 

The WLAN Interworking Mobility solution described in this TS provides a DSMIPv6 [7] based inter-system mobility 
solution on top of 3GPP I-WLAN, TS 23.234 [2] and 3GPP PS domain, TS 23.060 [3]. The inter-system mobility 
solution is compatible with pre-Release 8 TS 23.060 [3] systems and with pre-Release 8 TS 23.234 [2] systems. 

The inter-system mobility solution provides the following functions: 

HA discovery. 

- Security association establishment between UE and HA, including the required AAA interactions. 

- DSMIPv6 signalling and user data transfer between UE and HA. 
The inter-system mobility solution has the following limitations: 

- No support for Network Initiated Service Request procedures. 
No support for PCRF -HA interactions. 

- No updates to the existing PCRFs. 

- No updates to the existing PCC signalling. 

- No updates to the existing PCEF functionality in GGSN and PDG. 

NOTE: This means that the PCEF in GGSN and PDG can not operate on service data flows inside the tunnel 
between UE and HA. 

Extending DSMIPv6 based inter-system mobility, to avoid the above limitations, requires deployment of EPS PDN 
GW. EPS PDN GW and its interactions with other 3GPP system nodes are specified in TS 23.402 [6]. 

Further EPS migration aspects are described in Annex A of this specification. 

5.3.2 Home Agent Discovery 

DSMIPv6 requires that the UE knows the HA IP address in order to establish the security association with home agent 
and then, to proceed to binding updates. This address is made known to the UE with one of the following ways: 

1) The IP address of the home agent is statically configured in UE, typically through a manual method, and is 
permanent until manually changed. 

2) The IP address of the home agent can be retrieved from DNS. 

3) The IP address of the home agent can be delivered to the UE via PCO. 

4) The PDG may return the IP address of the home agent in IKEv2 configuration payload to the UE. 

NOTE: The underlying IP access network may support other ways of configuring the HA IP address to the UE, 
but this is out of the scope of this specification. 

5.3.3 Home Link Detection 

The DSMIPv6 Home Link Detection Function is used by the UE to detect, if for a specific PDN, an access interface is 
the Home Link from DSMIPv6 perspective. 

It is up to the UE's configuration to decide when to trigger the home link detection function for a specific PDN 
connection. Before performing DSMIPv6 registration over any PDN connection, the UE must determine that it is not on 
its home link. 

The home link detection function compares: 
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- IPv6 prefix associated with a specific access interface of the UE; and 

Home Network Prefix (HNP) allocated to the PDN connection. 

If the two prefixes match, the UE detects it is in the home link for this specific PDN over the access interface. 
Otherwise, the UE detects it is not in the home link for this specific PDN over the access interface. 

NOTE 1 : The UE knows the IPv6 prefix associated with a specific access system interface via IP address allocation 
mechanisms applied in that access system. 

The UE knows the HNP allocated to the PDN connection from: 

- the IPsec security association bootstrap with the HA; or 

- the PCO delivered to UE at 3 GPP attach during the PDP context creation procedure to the GGSN in 2G/3G; or 

- from the IKEv2 sent to the UE during the IPsec tunnel establishment to the PDG in I-WLAN. 
The GGSN and PDG can get the HNP of the UE by means such as DHCP or AAA. 

NOTE 2: The HNP may also be pre-configured in the UE. 

5.4 Network Elements 

Home Agent (HA): 

The Home Agent communicates with the UE and exchanges DSMIPv6 related signalling to keep track of the 
access network the UE is recently camping on. This signalling is transparent to the Access Routers (AR) (GGSN 
and PDG). 

HA functionality may be implemented as a stand-alone HA entity, or co-located with GGSN or PDG. The 
special considerations of the HA-GGSN and HA-PDG co-location are described in Annex B of this 
specification. Configuring the GPRS system as the home link also for a standalone HA is not precluded. The 
home link is the link on which the UE's home subnet prefix is defined (see RFC 3775 [8]). 

UE: 

The UE contains a DSMIPv6 Client to enable the DSMIPv6 based signalling and user data transfer towards the 
Home Agent. 

5.5 Reference Points 

HGi: This reference point defines the interface from the HA to external PDN 

HI: This is the reference point for signalling and user data transfer between UE and HA. 

NOTE: HI may be transported over IP connectivity provided by I-WLAN or 3GPP access system. 

H2: This reference point defines the interface between HA and 3GPP AAA infrastructure (3GPP AAA server 

or 3GPP AAA proxy) and is used to transport authentication, authorization and charging-related 
information in a secure manner. 

H3: This is the IP transport reference point to carry the end-to-end UE-HA signalling and user data between 

Access Router and HA. Since there is no direct signalling messages between these two entities this is 
simple IP transport reference point, which does not require additional specification. 
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Functional Description and Information Flows 



6.1 



H1 PDN Attach 



HI PDN Attach is triggered by the UE to initiaUze the I-WLAN Mobility service towards a specific PDN. For each 
PDN connection, the HI PDN Attach has to be performed separately. 

NOTE 1: The HI PDN Attach is creating a PDN specific HI instance between a UE and a HA. 

NOTE 2: To execute HI PDN Attach via GPRS, the UE shall have Primary PDP context to GGSN from which the 
discovered HA can be reached via H3. 

When connected over the UE home link (e.g. 3GPP access), the UE may be configured not to trigger the establishment 
of IKEv2 SA. In this case, HI PDN Attach is triggered when the UE moves to I-WLAN. During the Handover the UE 
keeps using the source 2G/3G) access (i.e. make-bef ore-break). 



UE 



HA 



1 . HA discovery 



2. IKEv2 Security Association establishment 
& IPv6 HoA allocation 




3. Binding Update 



4. Binding Acknowledgement 



5. Child SA establishment 
for enhanced security 



3GPP AAA 
Proxy 



2. Auth. 



3GPP AAA 
Server 



n 



Authorization 



Figure 6.1 : H1 PDN Attach 

1. The UE discovers the Home Agent as defined in the clause 5.3.2, Home Agent Discovery. 

2. A security association is estabHshed between UE and HA to secure the DSMIPv6 messages related to this PDN 
connection between the UE and the HA. The UE initiates the establishment of the security association using 
IKEv2 [9]; EAP [10] is used over IKEv2 for authentication purposes. The HA communicates with the AAA 
infrastructure in order to complete the authentication. 

During this step an IPv6 home address/prefix is assigned by the HA to the UE as defined in RFC 4877 [11] and 
RFC 4306 [9]. During this step the UE may include the HA-APN of the PDN it wants to access (in the IKE 
AUTH message using the IDr payload in similar manner as specified for I-WLAN in TS 23.234 [2]) and it can 
also request a specific IPv6 home address as defined in RFC 4877 [11] in order to influence the IP address/prefix 
assignment procedure. 

In this step, the HA may be either in the HPLMN or in the VPLMN. When the HA is in the VPLMN, the 
interaction between the HA in the VPLMN with the AAA/HSS in the HPLMN may involve a 3GPP AAA Proxy 
in the VPLMN as specified in TS 23.234 [2]. 

If the PDN requires an additional authentication and authorization with an external AAA Server additional 
authentication is executed in this step. Details on these multiple authentications are specified in RFC 4739 [12] 
and in TS 23.234 [2] for I-WLAN (Private Network Access (PNA)). 
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3. In case a Binding Update is required to establish the desired PDN connectivity (e.g. UE is not at it's home link), 
the UE sends the DSMIPv6 Binding Update message to the HA as specified in draft-ietf-mip6-nemo- 
v4traversal [7]. 

The HA processes the Binding Update. During the processing the HA performs local authentication and 
authorization of the message using the IPsec security association established in step 2. If the UE does not have 
an IPv4 HoA already, it requests for the IPv4 home address from the HA as defined in draft-ietf-mip6-nemo- 
v4traversal [7] in this step. 

4. The HA sends the DSMIPv6 Binding Ack to the UE. In this step the HA may include an IPv4 home address as 
specified in draft-ietf-mip6-nemo-v4traversal [7] if requested by the UE in step 3. 

5. The HA may additionally trigger the creation of a child IPsec Security Association for protecting the traffic sent 
via the HI reference point. The child SA is created as specified in RFC 4877 [22]. Child SA can be used for HI 
IP flow integrity protection and may be used also for HI IP flow encryption. 

NOTE 1 : The child S A can be established and/or released by HA at any time after the IKEv2 bootstrap and not only 
just after step 4. 

NOTE 2: In a roaming scenario, the usage of the child SA for HI IP flow encryption by HPLMN HA may be 
restricted by the policies in the roaming agreement between the VPLMN and the HPLMN. 



6.2 



H1 PDN Detach 



The HI PDN Detach is clearing the PDN specific HI instance between a UE and a HA. This HI PDN detach has no 
impact to the status of possibly existing other HI based PDN connections nor to the underlying IP access connectivity 
state e.g. within GPRS system. 

6.2.1 UE Initiated Detach 

The Detach procedure when initiated by the UE is illustrated below. 
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1. Binding Update 



2. Binding Acknowledgement 




3. IKEv2 Security Association tear down 



3GPP AAA 
Proxy 



3GPP AAA 
Server 



4. H2 session termination 

7)^ 



] 



Figure 6.2-1: UE Initiated Detach Procedure 

1. If a Binding exists, the UE sends the DSMIPv6 Binding Update message to the HA as specified in draft-ietf- 
mip6-nemo-v4traversal [7]. UE indicates Binding Lifetime as 0. The HA processes the Binding Update. During 
the processing the HA performs local authentication and authorization of the message using the existing IPsec 
security association. 

2. The HA sends the DSMIPv6 Binding Ack to the UE. 
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3. UE triggers the tear down of the security association between UE and HA using IKEv2 [9]. The HA 
acknowledges the security association removal. 

4. The HA communicates with the AAA infrastructure in order to tear down the H2 session (unless needed to be 
maintained for other purposes). 

In this step, the HA may be either in the HPLMN or in the VPLMN. When the HA is in the VPLMN, the 
interaction between the HA in the VPLMN with the AAA/HSS in the HPLMN may involve a 3GPP AAA Proxy 
in the VPLMN as specified in TS 23.234 [2]. 

6.2.2 HA Initiated Detach 

The detach procedure when initiated by the HA is illustrated below. 



UE 
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1 . Detach Request 



2. Detach Acknowledgement 



3. IKEv2 Security Association tear down 



3GPP AAA 
proxy 



3GPP AAA 
server 



4. H2 session termination 



Figure 6.2-2: HA Initiated Detach Procedure 

1 . In the explicit detach procedure the HA shall send a detach request message as specified. In the implicit detach 
procedure this step is omitted. 

2. In the explicit detach procedure, the UE shall acknowledge the detach request. In the implicit detach procedure 
this step is omitted. 

NOTE: How the detach request and acknowledge messages are implemented is a stage 3 detail. 

3. UE triggers the tear down of the security association between UE and HA using IKEv2 [9]. The HA 
acknowledges the security association removal. 

4. The HA communicates with the AAA infrastructure in order to tear down the H2 session (unless needed to be 
maintained for other purposes). 

In this step, the HA may be either in the HPLMN or in the VPLMN. When the HA is in the VPLMN, the 
interaction between the HA in the VPLMN with the AAA/HSS in the HPLMN may involve a 3GPP AAA Proxy 
in the VPLMN as specified in TS 23.234 [2]. 

6.2.3 AAA Initiated Detach 

The Detach procedure when initiated by the AAA is illustrated below. 
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Figure 6.2-3: AAA Initiated Detach Procedure 

1. If the AAA wants to request the immediate termination of an HI session for a given UE, it shall send a Session 
Termination message to the HA. In the roaming case signalling may be routed via a 3 GPP AAA Proxy in the 
VPLMN. 

2. The HA initiated detach procedure is performed as defined in clause 6.2.2, Figure 6.2-2. 



6.3 



Handover 



6.3.1 H1 Reference Point Procedure 

This procedure is used to bind access specific Care-of Address with the Home Address. This procedure is performed to 
either refresh an existing binding or to change the binding from one Care-of Address to another when the Care-of 
Address changes e.g., due to movement between GPRS and I-WLAN. When this procedure is triggered it is assumed 
that the UE already has an IP address from the underlying IP access system. 

In this procedure it is assumed that the UE is already HI PDN Attached. 



UE 



HA 



1. Binding Update 



2. Binding Acknowledgement 



Figure 6.3.1-1: Binding Update Procedure 

1. The UE sends the DSMIPv6 Binding Update message to the HA as specified in draft-ietf-mip6-nemo- 
v4traversal-03 [7]. HA performs local authentication and authorization of the Binding Update message using the 
existing IPsec security association 

2. The HA sends the DSMIPv6 Binding Ack to the UE as specified in draft-ietf-mip6-nemo-v4traversal-03 [7]. 
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6.3.2 Handover Signalling Flows 



6.3.2.1 



Handover from 3GPP l-WLAN to 3GPP access 



The information flow represents a handover scenario from 3GPP I-WLAN access to 3GPP access for both the home 
mobility service and the visited mobility service cases (HSS and 3 GPP AAA server are left out for simplicity). 



UE 



SGS 
N 



PDG 



1. UE Discovers 

3GPP access 

and initiates HO 



2. GPFIS Attach/PDP context 



GTP Tjnnel 



3. Binding Update 



GGSN 



activation 



HA 



4. Binding Acknowledgement 



Figure 6.3.2.1-1 : Handover from 3GPP l-WLAN access to 3GPP access 

1. While connected over l-WLAN, the UE discovers the 3GPP GPRS coverage and determines to transfer its 
current sessions from the currently used 3 GPP l-WLAN access to the discovered 3 GPP access system. 

2. The GPRS attach procedure including GGSN selection, IP address assignment to the UE, etc., is involved as 
specified in TS 23.060 [3]. The GTP tunnel between UE and GGSN is finally established and the UE can 
transfer data via 3 GPP access. 

3. The UE sends the DSMIPv6 Binding Update message to the HA as specified in draft-ietf-mip6-nemo- 
v4traversal [7]. 

A. If the UE is on the home Hnk, the UE sends a BU with LIFETIME==0. 

B. If the UE is not on the home link, the UE sends a regular BU. 

4. The HA sends the DSMIPv6 Binding Ack to the UE as specified in draft-ietf-mip6-nemo-v4traversal [7]. The 
DSMIPv6 tunnelling is modified accordingly. 



6.3.2.2 



Handover from 3GPP access to 3GPP l-WLAN access 



The information flow represents a handover scenario from 3 GPP access to 3 GPP l-WLAN access for both the home 
mobility service and the visited mobility service cases (HSS and 3 GPP AAA server are left out for simplicity). 
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DSMIPV6 
tunnel 





Figure 6.3.2.2-1 : Handover from 3GPP access to 3GPP l-WLAN access 

1. The UE discovers the 3GPP I-WLAN coverage and determines to transfer its current sessions from the currently 
used 3 GPP GPRS access to the discovered 3 GPP l-WLAN access system. 

2. The UE estabHshes an IPsec tunnel with PDG according to TS 23.234 [2]. 

3. If HI PDN attach is not already executed, UE triggers HI PDN attach via l-WLAN. If HI PDN attach is already 
executed the UE triggers a Binding Update via l-WLAN. 

4. As the result of HI PDN attach or Binding Update, DSMIPv6 tunnel is established/re-estabslihed between UE 
and HA, and UE can transfer data via 3 GPP l-WLAN access. 



6.4 Accounting 



H2 reference point supports transfer of accounting related information between the HA and 3 GPP AAA infrastructure. 
The accounting related functionality in H2 reference point is based on accounting functionality for the Wa reference 
point specified in TS 23.234 [2]. 

As stated in the requirement section. It should be possible to perform charging differentiation based on radio access type 
the user is connected for collocated GGSN/HA and for separate GGSN and HA based architecture. The charging system 
may use the UE IP address to correlate the IP session between GPRS and l-WLAN and the NAS ID / NAS-IP address 
which correspond either to the GGSN or PDG or HA to derive the radio access type the user is connected to. 

NOTE: How the charging differentiation based on radio access type the user is implemented is a stage 3 detail. 



6.5 



Interactions with Other Services 



When the UE moves between l-WLAN and GPRS network, as the same IP address is kept, there is no need to re- 
register with the IMS network. There is no impact to the IMS services. 

NOTE 1 : A new registration to inform the network of changes of the access radio link (e.g. different capability) 
may be needed. In this case, because the P-CSCF has already been discovered in source access system, 
the re-registration in from the target access system is according to standard IMS registration. 

NOTE 2: Current P-CSCF discovery mechanisms described in TS 23.228 are re-used. 
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Annex A (Normative): 

EPS Migration Considerations 



Extension of the DSMIPv6 based inter-system mobility with additional functionality, such as PCRF interactions, 
requires deployment of EPS PDNGW, containing the HA functionality. EPS PDN GW and its interactions with other 
3GPP system nodes are specified in TS 23.402 [6]. 

The intention is not to extend the introduced HA entity to support these additional release 8 functions of PDN GW. 
Thus enabling these additional functions requires migration to EPS. 

Figure A-1. illustrates a possible migration path to EPS. 



PCRF 
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Server 



Combined 
UE 



S2c 



Access 
Router 



TP/PMIP PDNGW 



I "" 

H3 




S6b 



SGjJ External 
I PDN 



Other 3GPP nodes 
interacting with PDNGW 



Figure A-1 : A possible migration to EPS 

Reference point considerations: 

- The HI should be a subset of S2c. 

- The HGi should be a subset of SGi. 

- The H2 should be a subset of S6b. 
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Annex B (Normative): 

Information on implementation options 

B.1 Co-located HA and GGSN functions 

It shall be possible to configure the GPRS access system as the DSMIPv6 "home link". In this case the IP address 
allocated to the UE by the GPRS system (as specified in TS 23.060 [3]) is used as the Home Address for DSMIPv6 and 
so, DSMIPv6 user plane encapsulation is not used over the GPRS system. 

B.1 .1 Home Mobility Service Architecture 

The Home Mobility Service architecture in integrated scenario refers to the case where the Home Agent function locates 
within the GGSN. 

The UE access the operator PS Services via the radio interface labelled Um in A/Gb mode and Uu in lu mode for 
mobile access. 

The UE access the operator PS Services via the radio interface labelled Ww for I-WLAN access. 

PDP contexts each of them using one unique PDF address are independent to each other. The terminating access points 
of these different primary PDP contexts could be located in the same or in different GGSN/HA's. 
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Figure B-1 : Co-located HA and GGSN architecture 



B.1 .2 Home Link Discovery for the Co-located HA and GGSN 

This section introduces the usage of Protocol Configuration Options (PCO) for the home Hnk discovery when UE 
attaches to GPRS which is configured as UE's home link. PCO may be used to transfer IP address of Home Agent and 
Home Network Prefix between the UE and the GGSN. 

The IP address of Home Agent is the IP address of the Co-located HA/GGSN, which is used as the home agent when 
UE hands over to I-WLAN. 
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B.1.3 3GPP Attachment 

In the collocated GGSN/HA architecture, the Mobile Node is in the home link in 2G/3G. In this case, it does not need to 
use mobile IP signalling and encapsulation and it will use the PDP Address as the Home Address (Ho A). 

The 3GPP attachment procedure is unchanged. The 2G/3G network is assumed to be the home link therefore HI PDN- 
Attach is not performed. 

The following procedure describes the attach procedure over 2G/3G for the GGSN and HA collocated scenario. 
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Figure B-2: PDP Context Activation with mobility 

1. The UE initiates the attach procedure at power on. The UE is authenticated and authorized to access the 2G/3G 
network according to TS 23.060 [3]. SGSN may interact with the HLR for Authentication. 

2. The SGSN interacts with the HLR and updates the mobile node's location area as it is specified in TS 23.060 [3]. 
SGSN receives the Subscriber Data from HLR. 

3. The UE initiates the PDP context activation procedure as it is specified in TS 23.060 [3] to obtain the IP address. 
The Access Point Name (APN) specified by the service provider may be passed as a parameter. The UE shall 
leave the PDP Address empty to request a dynamic PDP address. 

4. The SGSN performs the GGSN selection as it is specified in TS 23.060 [3]. 

5. The SGSN requests the selected GGSN to set up a PDP context for the UE as it is specified in TS 23.060 [3]. 

6. If the GGSN can assign an address for the UE locally, it assigns the address and the GGSN creates a TEID for 
the requested PDP context. Otherwise the GGSN uses External PDN Address Allocation mechanism as it is 
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specified in TS 23.060 [3] and in TS 29.061 [13]. The GGSN obtain a PDP address from the PDN by means of 
protocols such as DHCP or RADIUS and creates a TEID for the requested PDP context. 

7. The GGSN responds back to the SGSN, indicating completion of the PDP context activation procedure as it is 
specified in TS 23.060 [3]. The PDP address, which is sent back to the UE, is the Home Address. In addition to 
the GPRS specification TS 23.060 [3] the GGSN may return the Home Link information including the HA 
address via the PCO to the UE. 

8. The SGSN replies back to the UE as it is specified in TS 23.060 [3]. This signals completion of the PDP context 
activation and the IP address allocated corresponds also to its HoA. 

NOTE 1: As the UE is on the home link, HI PDN- Attach is not performed. How the UE detects that it is on the 
home link is described in Home link discovery section. 

NOTE 2: The HA address may be returned to the UE discovered at handover by DNS. 

B.1 .4 l-WLAN Attachment 

The UE powers on over I-WLAN and performs I-WLAN attach procedure according to TS 23.234 [2] and HI PDN 
Attach to the HA according to this TS. The DSMIPv6 BU/BA to the Home Agent is triggered by the UE. 

NOTE: How the UE discovers the HA is defined in HA discovery section (see clause 5.3.2 Home 

Agent Discovery). 
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Figure B-3: I-WLAN Attach with mobility service 
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1. The WLAN UE selects a WLAN Access Network and establishes the WLAN connection with a WLAN 
technology specific procedure. The UE gets allocated a local IP address and optionally WLAN Access 
Authentication and Authorization which may depend on the home operator policy as well as the policy of the 
provider of the WLAN AN according to TS 23.234 [2]. 

2. LWLAN attachment and IPsec tunnel setup is executed according to TS 23.234 [2]. In addition to the procedure 
defined in TS 23.234 [2]. The PDG may return the HA address in IKEv2 configuration payload to the UE. 

3. The method by which HA is known to the UE is defined in HA discovery clause 5.3.2 The UE must know the 
HA in order to perform BU/B A. This step is required only if HA address was not discovered via IKEv2 
configuration payload in the previous steps. 

4. HI PDN- Attach procedure is performed as it is specified in clause 6.1. 

5. The UE can send and receive packet. 

B.1 .5 Handover from 3GPP access to l-WLAN 
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Figure B-4: Handover from 3GPP access to l-WLAN 
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1. The precondition of this flow is that the UE is attached to a 3GPP access and has active PDP context(s) with a 
GGSN/HA node. There is a GTP tunnel between the SGSN and the GGSN. 

2. The UE needs to handover to a WLAN access network. The HO decision mechanism could be based on local 
policy in the UE. 

3. I-WLAN attachment and IPsec tunnel setup is executed according to TS 23.234 [2]. In addition to the procedure 
defined in TS 23.234 [2] the UE may also obtain the Home Agent information via IKEv2 configuration payload 
if not already available in the UE. 

4. The UE perform IKEv2/IPsec security association setup procedure with the Home Agent for DSMIPv6. 

5. The UE sends a binding update to its home agent to update the binding cache entry at the home agent. The UE 
will use its IP address used in 3 GPP access as its Home Address. This address will be preserved unless further 
indication from the 3 GPP access. The UE uses the address configured from the PDG as the care-of address. The 
care-of address may be an IPv4 or IPv6 address. 

6. The Home Agent responds with a binding acknowledgement if the binding update process was successful. The 
Home Agent also creates the binding cache entry with the new care-of address of the UE. 

7. The successful exchange of binding update and binding acknowledgement results in a Mobile IP tunnel between 
the UE and the home agent over the IPsec tunnel between the UE and the PDG. Data packets are now routed by 
Home Agent to UE's Care-of- Address via I-WLAN. 

8. During this procedure, bearer resources reserved for the UE are released. 

B.1 .6 Handover from I-WLAN to 3GPP Access 

The handover may take place when the source network is no longer able to provide the required user-to-PDN 
connection service or based on operator policies. 
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B.1 .6.1 DSMIPv6 operation 
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Figure B-5: Handover from l-WLAN to 3GPP Access 

1 . The precondition of this flow is that he UE is attached over I-WLAN with mobiUty support. There is a Mobile IP 
tunnel between the UE and the Home Agent over an IPsec tunnel between the UE and the PDG. 

2. The UE may need to handover to 3GPP access network because l-WLAN is no longer able to provide the 
required user-to-PDN connection service or based on operator policies. The UE attaches to 3 GPP access 
according to TS 23.060 [3]. 

In order to generate an APN to be used when activating a PDP context in the GPRS access, the UE uses one of 
the following options: 

a. An APN corresponding to the combined GGSN/HA used in source access may be pre-configured in the UE. 

b. In case the APN is not statically configured, the UE makes a reverse DNS lookup of the HA IP address. As 
reply from the DNS server, the UE receives an APN corresponding to the combined GGSN/HA. 

3. The UE initiates PDP context setup according to TS 23.060 [3]. The UE provides an APN corresponding to the 
combined GGSN/HA used in the source access. This results in a PDP context setup with a GTP tunnel between 
the SGSN and the GGSN. GGSN returns a PDP address to the UE which is same as the HoA the UE used in 
WLAN access in step 1. In case of IPv6, the prefix associated with the PDP context is the same as the one for 
HoA (i.e. HNP). 
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4. The GGSN/HA interacts with the AAA server for mobility service authentication and authorization according to 
TS 29.061 [13]. 

5. The UE detects that the Ho A and the PDP address are same, so the UE considers itself in home link. The UE 
sends a Binding Update to its home agent with lifetime=0, and CoA=HoA to delete the binding cache entry at 
the home agent. 

6. The Home Agent responds with a Binding Acknowledgement if the binding update process (binding deletion) 
was successful. 

7. With the Binding Update and binding acknowledgement exchange the HA recognizes that the UE has returned 
home and deletes the binding cache. There is no Mobile IP tunnel between the UE and the home agent however a 
GTP tunnel is estabHshed between the SGSN and the GGSN. 

8. Bearer Resources on the I-WLAN access system are released according to TS 23.234 [2]. For that the UE 
detaches from I-WLAN if it has not happened before. 



B.2 Co-located HA and PDG functions 

It shall be possible to co-locate the HA and PDG. The GERAN/UTRAN may still acts as the home link. In this case the 
IP address allocated to the UE by the GPRS system is used as HoA for DSMIPv6. 

B.2.1 H1 PDN Attach 

The HI- PDN Attach procedure for co-located PDG and HA is based on the attach procedure described in clause 6.1. 
When attached to the co-located PDG+HA, the UE may be on the home link. How the UE finds it's in the home link is 
described in clause 5.3.3 Home Link Detection. 
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